CVE Vulnerabilities

CVE-2022-25940

Published: Dec 20, 2022 | Modified: Apr 16, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.

Affected Software

NameVendorStart VersionEnd Version
Lite-serverLite-server_project- (including)- (including)

References